CVE-2026-41374 PUBLISHED

OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization

Assigner: VulnCheck
Reserved: 20.04.2026 Published: 28.04.2026 Updated: 28.04.2026

OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without member allowlist validation to cause resource exhaustion.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor OpenClaw
Product OpenClaw
Versions Default: unaffected
  • affected from 0 to 2026.3.31 (excl.)
  • Version 2026.3.31 is unaffected

Credits

  • AntAISecurityLab reporter

References

Problem Types

  • CWE-408: Incorrect Behavior Order: Early Amplification CWE